# PhishDestroy threat dossier — home-apps-jupiter.wixstudio.com ================================================================ Fetched: 2026-06-29 21:40:33 UTC Canonical: https://phishdestroy.io/domain/home-apps-jupiter.wixstudio.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 62/100 (PhishDestroy scoring — see methodology below) Targeted brand: Jupiter ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Cluster25, Gridinsoft, PREBYTES, Webroot Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- Registrar: GoDaddy.com, LLC Nameservers: ["dns1.p08.nsone.net", "dns2.p08.nsone.net", "dns3.p08.nsone.net", "dns4.p08.nsone.net"] Registered: 2026-06-08 Page title: Jupiter Swap®™ HTTP response: 404 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-08 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-09 05:31:19 UTC (by PhishDestroy tracker) First reported: 2026-06-15 00:27:29 UTC (abuse notice filed) Last verified: 2026-06-29 20:20:35 UTC Neutralised: 2026-06-09 06:27:53 UTC Current status: taken down (registrar suspended or DNS dead) ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-26 01:25:55 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, home-apps-jupiter.wixstudio.com, is identified as a brand impersonation threat specifically targeting Jupiter, a known entity in the cryptocurrency sector. The site mimics legitimate Jupiter services, presenting itself under the title 'Jupiter Swap®™' to deceive users into engaging with fraudulent swap or transaction interfaces. Such impersonation schemes are commonly used to deploy crypto drainers, siphoning digital assets from unsuspecting victims through malicious smart contracts or fake wallet integrations. The presence of this domain poses a direct financial risk to users who may unknowingly authorize transactions or disclose sensitive credentials. Analysis indicates multiple concrete indicators of compromise. The domain was registered on June 08, 2026, through GoDaddy.com, LLC, and is currently offline. It appears on one security blocklist and has been flagged by 5 out of 95 security vendors on VirusTotal, signaling its malicious intent. Infrastructure analysis reveals the use of Wix hosting, React for frontend development, and Google Cloud for backend services, which are legitimate technologies but frequently exploited in fraudulent schemes. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious sites, and the domain employs HTTP/3 and HSTS, which do not mitigate its fraudulent nature. Users who have visited home-apps-jupiter.wixstudio.com should take immediate action to secure their assets and accounts. If any interaction occurred, such as connecting a wallet or entering credentials, revoke all active smart contract approvals associated with the domain using a trusted blockchain explorer. Monitor connected wallets for unauthorized transactions and consider transferring assets to a new, secure wallet if compromise is suspected. Additionally, scan local devices for malware, as some crypto drainers deploy secondary payloads to maintain persistence. Report the domain to relevant security platforms to aid in broader threat mitigation efforts. ## EVIDENCE HASHES ---------------------------------------------------------------- Favicon MD5: 9dae2d380288ac898efffb0f06444e23 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/home-apps-jupiter.wixstudio.com/ JSON API: https://api.destroy.tools/v1/check?domain=home-apps-jupiter.wixstudio.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,677 domains (13,179 alive under monitoring, 158,908 confirmed takedowns/dead). Site: https://phishdestroy.io